US Privacy Policy & Legal Terms
Last Updated: June 26, 2026
Community Partnership & Data Responsibility
This document honors and governs all users residing in the United States (US). Throughout this agreement, the community leader integrating the bot is warmly referred to as the "Guild Owner".
Aegitox is proud to operate as your B2B Infrastructure Provider (Service Provider / Data Processor). By uniting our bot with your server via Discord OAuth2, you step into the vital role of the Primary Data Controller. Together, we ensure your server operates in perfect harmony with state and federal laws. You take the lead in ensuring your server's use of our AI moderation complies with the CCPA/CPRA, the TAKE IT DOWN Act, and your local digital privacy frameworks.
Jurisdiction Notice:
If you are a resident outside the US and EU, please proceed to our Global Privacy Policy
If you are a resident of the European Union, EEA, or UK, please proceed to our fully compliant EU Privacy Policy
1. Data Minimization & Our Anti-Data Broker Promise
In beautiful alignment with the CCPA/CPRA, we collect specific Identifiers strictly to make the magic happen. This includes cryptographic identifiers (Discord User IDs, Guild IDs) and dynamically cached display data (Discord Usernames, Server Names) required solely to render fun, contextual analytics and Karma Reports for you, the Guild Owner. We also cache Inferences (like Karma scores and violation metrics) to help you shape your community's vibe.
Protecting Your Server's Sanctuary: We want to be crystal clear: Aegitox is NOT a Data Broker. While we display real usernames on your private server-specific leaderboards, our architecture enforces strict Row-Level Security (RLS) in our PostgreSQL database. Your members' behavioral profiles and cached display names are mathematically sealed within your Discord Server. We absolutely do not track, cross-pollinate, or sell global user profiles across different communities. What happens in your server, stays in your server.
2. Understanding AI Nuance & Generative Content
- Our Role as an AI Deployer (CA AB 2013 & Utah AI Act): Aegitox operates as an AI Deployer of third-party foundational models (OpenRouter Enterprise Cluster). For local edge inference, Aegitox utilizes MiniLM-L6-v2 running exclusively on unmodified, publicly available pre-trained weights. No custom fine-tuning, weight adjustment, or performance-altering training has been performed on this model using user-sourced data, exempting Aegitox from developer obligations under California AB 2013 (effective January 1, 2026). Should any future local model optimization occur, a training data transparency summary (dataset sources, volume, and personal data usage) will be published to this page prior to deployment, in strict compliance with AB 2013. Because generative AI is probabilistic, you kindly agree to hold us harmless from any AI "hallucinations," factual inaccuracies, or quirky outputs generated during these split-second inferences.
- Privacy by Design (Volatile Processing): To champion user privacy under state frameworks, Aegitox processes the vast majority of traffic natively on the edge. For PRO-tier deep semantic analysis, we enforce Global Zero Data Retention (ZDR). Text payloads exist only in Volatile RAM just long enough for the AI to read them, and are then permanently purged into the void. All external cloud inference integrations (including OpenRouter, Inc.) operate exclusively under enterprise-tier API agreements containing contractually binding Zero Data Retention (ZDR) and Zero Training guarantees. These providers are legally prohibited from retaining, logging, sampling, or utilizing any Aegitox-routed user chat payloads for AI model training, fine-tuning, or optimization purposes, in strict compliance with Discord Developer Policy Section 21.
- Swift Action & TAKE IT DOWN Act (2025) Compliance: We have zero tolerance for illegal content. Any valid, verified request regarding non-consensual or illegal AI-generated content will be definitively expunged from our systems within 48 hours. Let's keep the internet safe.
- Building Trust Through Transparency (FTC, CA SB 1001): We believe users should always know who they are talking to. By default, all text lovingly paraphrased by our AI engine is clearly labeled (e.g., "✨ Upgraded by Aegitox AI") to prevent confusion and maintain algorithmic honesty.
3. Fun Metrics, Not Real-World Scoring (ADMT Exemption)
The FCRA Exemption: Our "Karma" metric is a fun, internal gamification tool designed to reward positive vibes. It absolutely does NOT constitute a Consumer Report, credit score, or psychological profile under the Fair Credit Reporting Act (FCRA). We ask that you never use it for real-world decision-making.
Colorado AI Act Exemption & The Human Element: Aegitox algorithms are NOT classified as "High-Risk AI Systems," and our helpful automated timeouts are NOT "Consequential Decisions" affecting housing or employment. Furthermore, any automated timeout includes a simple dispute mechanism. Final disciplinary authority always remains with you, the human Server Administrator.
Workforce Carve-Out & Acceptable Use Prohibition (Colorado SB 26-189): Effective May 2026, Colorado SB 26-189 regulates Automated Decision-Making Technologies (ADMTs) that materially influence consequential decisions in employment contexts. Guild Owners deploying Aegitox within corporate, enterprise, or professional Discord environments are strictly and explicitly prohibited from using Karma scores, violation metrics, or automated moderation histories to inform, influence, or support hiring, promotion, compensation, or disciplinary decisions regarding employees or job applicants. Such use constitutes deployment of an ADMT under Colorado law and is a material breach of this agreement. Aegitox accepts no liability for Guild Owner misuse of community metrics in workforce contexts.
4. Cryptographic Security & Supporting Youth Safety
- Fortified Infrastructure & Secure Data Requests: We proudly defend against bad actors using a highly resilient
BoundedChannelsarchitecture in .NET 10. To prevent social engineering, Data Subject Access Requests (DSARs) are executed safely via cryptographically signed JWTs, generated exclusively by our systems after a secure Discord OAuth2 authentication. - Supporting Discord's Youth Safety (MODPA/COPPA): We trust and rely on Discord's excellent native age-gating mechanisms. For users aged 13-17, chat data is processed purely under the "Strict Necessity" standard—evaluated in volatile memory to protect the server and instantly destroyed. We never use, and strictly prohibit the use of, minor data for targeted advertising.
5. Our Trusted Technology Partners
To keep Aegitox incredibly fast and secure, we partner with industry leaders. In compliance with state laws like the Oregon OCPA, here is our transparent, US-based supply chain (unless otherwise noted):
- Hetzner Cloud: High-performance Bare-metal infrastructure.
- Cloudflare: Our robust Edge CDN and Web Application Firewall. Transitory IP processing helps us squash bugs and block DDoS attacks.
- Supabase: Highly secure PostgreSQL database management.
- OpenRouter, Inc.: Our Enterprise Inference Cluster, backing our promise of Global Zero Data Retention.
- Discord: Our incredible host platform.
- Firebase Hosting: Global Edge CDN delivering our beautiful Angular frontend safely to your browser.
- PayPro Global: Our dedicated Merchant of Record. We entrust all transactions to them to guarantee elite, PCI-compliant payment security.
- Cross-Border Operations Disclosure (Oregon OCPA / International Transfer Standards): Core platform engineering, database administration, and system monitoring are performed by Aegitox's technical operations team located in Ukraine. All administrative access to platform infrastructure is conducted over TLS 1.3 encrypted channels. PostgreSQL Row-Level Security (RLS) is enforced at the database level, ensuring that operational staff cannot access raw, unhashed user identifiers or plaintext message content outside of documented, time-bound, and auditable authorization windows.
- Discord Privileged Intent Compliance (June 2026): Aegitox accesses the MESSAGE_CONTENT Privileged Gateway Intent solely for real-time community safety inference. Per Discord's updated platform policy effective June 10, 2026, applications exceeding 10,000 unique users across all installed servers are subject to manual whitelisting review and annual re-verification by Discord. Aegitox monitors its unique user-base telemetry and proactively initiates re-verification upon approaching this threshold.
6. Community Leadership & Mutual Support
As the individual installing Aegitox, you are the Authorized Representative of your community. You take the wonderful responsibility of establishing your server's rules and letting your members know how our AI helps keep the peace.
Protecting Each Other (Indemnification): Because we simply provide the tools you use to build your community, you graciously agree to defend and hold Aegitox harmless from any external claims, legal fees, or disputes that arise from how the bot is configured or utilized within your specific server.
Clear Communication: If an unforeseen security event ever occurs, we are obligated to securely notify you, the Guild Owner. You then take the baton to transparently inform your amazing community members.
7. Resolving Disagreements Amicably (Arbitration & Limits)
While we hope to never need this, we must outline how we handle formal disputes to protect both your community and our team. Please review these boundaries carefully.
- Fair & Efficient Arbitration: Any disagreements will be resolved fairly through binding, confidential arbitration administered by JAMS (via remote teleconference), allowing us to avoid lengthy court battles.
- Individual Focus (Class-Action Waiver): To keep proceedings focused and equitable, we both agree to bring claims strictly in our individual capacities, entirely waiving the right to participate in class-action lawsuits.
- Predictable Boundaries (Financial Cap): To provide B2B software at scale, our total cumulative financial liability to you is safely capped at the amount you paid for Aegitox in the twelve (12) months preceding the claim, or $100.00 USD, whichever is greater.
- Timely Resolution: Any claims must be brought forward within one (1) year of the incident, ensuring we address concerns while they are fresh.
8. Honoring Global Trade Regulations
To maintain our pristine standing with cloud providers and financial partners, Aegitox strictly abides by U.S. Export Administration Regulations (EAR) and OFAC sanctions.
Respecting Boundaries: By joining us, you confirm you are not located in, or operating on behalf of, a comprehensively embargoed region (including Cuba, Iran, North Korea, Syria, Russia, and the sanctioned regions of Ukraine). You also confirm you are not on any U.S. restricted parties list (like the SDN List).
We value transparency. Using VPNs to mask your location specifically to bypass federal sanctions puts our entire platform at risk and forces us to immediately terminate the account without refund. Let's keep things honest.
9. Empowering Your Privacy & Secure Requests
You possess powerful rights concerning your data, including the right to Access, Delete, and Opt-Out of Profiling. We've built the tools to help you exercise them smoothly.
Secure Verification Requirement: To shield your community from malicious data deletion, we require strict cryptographic proof for these requests. Please execute privacy requests directly through our securely authenticated dashboard.
Secondary Verification Path (CCPA-Mandated): In compliance with the California Consumer Privacy Act's requirement for a minimum of two accessible request channels, privacy rights requests are also accepted via email at [email protected]. To prevent social engineering without requiring Discord OAuth2 access — which may be unavailable to banned or deactivated accounts — email-based requests undergo a manual verification flow: submit your raw Discord Snowflake ID, and our team will cryptographically verify it against logged server interaction telemetry or stored database hashes. This ensures banned and account-deleted users retain their full legal right to deletion. authenticated dashboard.
Strength in Structure (Severability): If any provision of this Global MSA is found unenforceable by a court of competent jurisdiction, that specific provision shall be limited to the minimum extent necessary, ensuring the absolute liability shield and remainder of the agreement remains in full force and effect.
For verified administrative inquiries, say hello: [email protected]
10. Security, Authentication & Local Storage
To deliver a seamless, high-performance, and secure experience, the Aegitox platform utilizes the browser's Web Storage API (LocalStorage) rather than legacy HTTP cookies. In strict alignment with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), we are committed to absolute transparency regarding the operational data residing on your device.
Strictly Necessary Business Purposes
We absolutely do not "sell" or "share" your LocalStorage data for cross-site tracking, third-party marketing, or behavioral profiling. The localized data is legally classified as a "Strictly Necessary Business Purpose" to provide the explicitly requested administrative dashboard. We strictly limit client-side storage to the following functional artifacts:
- discord_token: A cryptographically secure JSON Web Token (JWT) generated directly by our server immediately after successful Discord OAuth2 authorization. This token is used to maintain your stateless, authenticated session with our backend microservices.
- discord_user: A localized cache of your Discord profile metadata (such as your username and avatar) alongside an embedded adminGuilds array detailing your specific server permissions. To ensure the most efficient integration possible, we utilize client-side caching to reduce network request volume. This approach supports the overall health and stability of the Discord ecosystem by preventing API congestion, allowing us to deliver immediate interface hydration without taxing shared platform resources.
Zero-Trust Security Architecture
While user profile data and server lists are cached locally in your browser for UI performance, the Aegitox platform operates on a strict Zero-Trust security model. Our servers never trust the localized user interface payload for access control. Every administrative action and data request is independently and cryptographically re-validated server-side utilizing your secure JWT. This guarantees that even if local browser payloads are manually altered, unauthorized access or privilege escalation remains cryptographically impossible.
Data Retention and User Control
Because this localized storage is strictly necessary for core application functionality, session security, and rate-limit prevention, it operates under the functional exemptions of state privacy laws and does not require an active opt-out banner. This functional data remains on your device only for the duration of your active session. You maintain absolute, overriding control and can instantly purge all stored information by clicking "Logout" within the dashboard. Furthermore, as a proactive architectural security measure, our platform requires all users to automatically re-login every 12 hours. This guarantees that stale sessions are forcefully terminated and local storage artifacts are routinely wiped.
11. Data Deletion Exemptions & Security Architecture
We respect your right to request the deletion of your personal information and adhere to strict data minimization principles. However, to fulfill our existential security commitments to the community and remain in strict compliance with official Discord Developer Standards, specific retention exemptions apply to accounts that demonstrably violate platform integrity.[1, 2]
Discord Account Termination — Mandatory 7-Day Purge
In strict compliance with Section 2.4 of the Discord Developer Terms of Service, all End User Data (including Discord User IDs, cached usernames, avatars, karma scores, and server interaction telemetry) is permanently purged or irreversibly anonymized within 7 days of the End User's Discord account termination. This is handled programmatically via automated deletion webhooks, cryptographically verified using Ed25519 signature validation to ensure payload authenticity. The retention exemptions outlined below (Security and Financial bans) apply only to pseudonymized SHA-256 hashes — never to raw identifiable data — and remain subject to this 7-day window for all plaintext identifiers.
High-Risk Security Bans (IsBannedForSecurity)
Accounts involved in verified cyberattacks, malicious exploits, or severe platform abuse are flagged as critical security threats. Under California Civil Code § 1798.105(d)(2), we maintain the statutorily protected right to deny complete erasure requests for these entities.[6] Retaining this limited cryptographic telemetry is reasonably necessary and proportionate to help ensure security and integrity, and to protect against malicious, deceptive, fraudulent, or illegal activity.[7, 6]
Financial Disputes & Chargebacks (IsBannedForFinance)
Accounts that initiate hostile chargebacks or violate our financial terms are subject to permanent suspension. To balance your privacy rights with our operational integrity, we utilize a cryptographic pseudonymization strategy when handling deletion requests for these accounts.
Erasure Policy for Financial Suspensions: Your user profile and identifiable data have been successfully deleted. A cryptographic hash of your account identifier is securely stored on a suppression list solely to ensure compliance with our Terms of Service regarding previous financial disputes and chargebacks. Please note that separated financial transaction logs are preserved independently as mandated by state and federal tax, accounting, and anti-money laundering laws.